Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

A Windows Vulnerability found in your Calculator? Here’s What You Should Know

A Windows Vulnerability found in your Calculator? Here’s What You Should Know

Sometimes security breaches and hacking attacks come from the most unlikely of sources, even going so far as to utilize trusted applications to infect an endpoint or network. This is the case with a new phishing attack which uses the Calculator application that comes built-in with Windows in a very creative way. This is just one example of how hackers have been forced to innovate to combat the increasingly secure systems which businesses and users rely on today, and it should be a testament as to why you can never be too careful.

What is the Threat?

A security researcher who goes by ProxyLife on Twitter has reportedly discovered that there are several strains of malware and phishing attacks utilizing an outdated version of Microsoft’s Calculator application to find their way onto your network and launch their attacks—specifically the Windows 7 version of Calculator. The way that it works is that a cybercriminal tricks the user into downloading an ISO disc image which is disguised as a PDF or other similar file. This ISO contains a shortcut to an opened version of the Calculator application.

The Windows 7 Calculator can use what are called Dynamic Link Libraries in the same folder rather than defaulting to Windows’ system default libraries. The Calculator then runs the library, which is infected with malware. Later versions of Calculator do not have this capability, hence why an older version is necessary. Since Windows thinks that Calculator is a legitimate application, opening it in this way doesn’t set off any red flags within the system.

Should You be Worried?

At the end of the day, this is largely an obscure threat that sees hackers using the tools at their disposal in creative and different ways. It is not yet known if Microsoft has issued an update to Defender to put a stop to these types of attacks, but the long and short of it is that you probably won’t encounter this specific threat, as long as you are using proper security practices while browsing the Internet or checking your email.

Still, the idea that threats can use trusted and known applications in this way can make things a bit of a hassle for your IT team. These types of attacks might bypass the defenses built into your operating systems, but they can be caught if you are proactively monitoring your infrastructure for abnormalities. These abnormalities can then be contained, isolated, and eliminated. Of course, the problem here is that you likely wouldn’t find this type of threat if you weren’t actively looking for it—which is where we come in.

Proactively Monitor Your Network with Our Services

We know that it can be a challenge to keep your network safe. That’s why we make it easy with our remote monitoring services. Combined with comprehensive security solutions like a firewall, antivirus, spam blocker, and content filter, you’ll find that your network has never been safer. To learn more about what we can do for your business, contact us today at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Sunday, 22 March 2026

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Efficiency Hardware Network Security User Tips Internet IT Services Malware IT Support Privacy Workplace Tips Phishing Google Email Computer Workplace Strategy Collaboration Hosted Solutions Small Business Users Backup Ransomware Managed Service Mobile Device Productivity Microsoft Passwords Quick Tips Saving Money Communication AI Cybersecurity Smartphone Data Backup Data Recovery Disaster Recovery Android Upgrade VoIP Business Management Smartphones Mobile Devices communications Windows Social Media Browser Microsoft Office Managed IT Services Network Current Events Tech Term Remote Internet of Things Information Holiday Artificial Intelligence Facebook Automation Miscellaneous Compliance Cloud Computing Covid-19 Training Gadgets Outsourced IT Server Managed Service Provider Remote Work IT Support Encryption Spam Employee/Employer Relationship Office Windows 10 Government Data Management Business Continuity Wi-Fi Blockchain Windows 10 Bandwidth Business Technology Virtualization Apps Data Security Two-factor Authentication Mobile Office Vendor Managed Services Employer-Employee Relationship Networking BYOD Mobile Device Management Chrome Gmail Budget WiFi Apple Tip of the week Voice over Internet Protocol App Managed IT Services How To Computing Hacker BDR Information Technology Avoiding Downtime Marketing Office 365 HIPAA Physical Security Applications Access Control Conferencing Healthcare Operating System Computers Risk Management Website Router Analytics Office Tips Augmented Reality Virtual Private Network Storage Health Password 2FA Bring Your Own Device Help Desk Big Data Retail Going Green Telephone Scam Data loss Customer Service Cybercrime Cooperation Free Resource Project Management Windows 7 Patch Management Save Money Microsoft 365 Remote Monitoring End of Support Vulnerability Vendor Management Solutions Firewall Display Printer Paperless Office Windows 11 Infrastructure The Internet of Things Monitoring Excel Document Management Social Managed IT Service Remote Workers Maintenance Customer Relationship Management Downloads Antivirus iPhone Settings Wireless Licensing Printing Content Filtering Vulnerabilities Hacking Entertainment YouTube Data Privacy Presentation Images 101 Cryptocurrency Wireless Technology Multi-Factor Authentication Robot Mobility Telephone System Cost Management Virtual Desktop Data storage LiFi Word IT Management Meetings Outlook VPN Employees Integration Money Modem Humor User Tip Processor Computer Repair Mobile Security Holidays Safety Sports Mouse Data Storage Smart Technology Supply Chain Video Conferencing Administration Machine Learning Managed Services Provider Virtual Machines Professional Services Saving Time Download Net Neutrality Twitter Alerts SQL Server Technology Care Business Communications Cortana Financial Data Error History Connectivity IT Social Engineering Break Fix Scams Alt Codes Browsers Smartwatch Downtime Upload Procurement Remote Computing Azure Hybrid Work Competition Multi-Factor Security Tech Human Resources Hosted Solution Social Network Telework Cyber security Tablet IoT Communitications Dark Web Cables Typing CES Trends Supply Chain Management Alert Google Drive Dark Data Google Calendar Term Google Apps User Knowledge Managed IT Customer Resource management FinTech File Sharing Regulations Data Analysis Star Wars IT Assessment How To Microsoft Excel IT Maintenance 5G Gamification Flexibility Notifications Staff Value Business Intelligence Travel Social Networking IP Address Google Docs Legislation Shortcuts Unified Communications Experience Organization Techology Fileless Malware Digital Security Cameras Google Maps Smart Devices Ransmoware Bitcoin Running Cable Google Wallet Content Remote Working Wearable Technology Memory Vendors Unified Threat Management Motherboard Data Breach Comparison Google Play Be Proactive Recovery Health IT Laptop Unified Threat Management Directions Videos Assessment Electronic Health Records Permissions Workforce Hard Drives Windows 8 Domains Drones Wasting Time Threats Trend Micro Network Congestion Specifications Security Cameras Workplace Strategies Halloween User Error Microchip Internet Exlporer Software as a Service Fraud Meta Refrigeration Public Speaking Username Managing Costs Amazon Point of Sale eCommerce Lithium-ion battery Black Friday SSID Entrepreneur Scary Stories Database Surveillance Virtual Assistant Outsource IT Hacks Media Fun Network Management Tech Support IT Technicians Virtual Machine Environment Cookies Monitors Cyber Monday Medical IT Deep Learning Proxy Server Reviews Tactics Development Hotspot Transportation Small Businesses Undo Education Websites Mirgation Hypervisor Displays Nanotechnology Optimization PowerPoint Shopping SharePoint Addiction Electronic Medical Records Language Employer/Employee Relationships Outsourcing Mobile Computing Navigation Search Management PCI DSS Chatbots Screen Reader Writing Distributed Denial of Service Workplace Application Best Practice Lenovo Gig Economy Buisness Service Level Agreement Internet Service Provider Virtual Reality Computing Infrastructure Teamwork Hiring/Firing IBM Legal Evernote Paperless IT solutions Server Management Regulations Compliance Private Cloud Identity Identity Theft Smart Tech Memes Co-managed IT Business Growth Superfish Bookmark

Blog Archive